Latest CVE Feed
-
6.1
MEDIUMCVE-2017-18006
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.... Read more
Affected Products : portfolio_netpublish- Published: Jan. 01, 2018
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-17994
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.... Read more
Affected Products : biometric_shift_employee_management_system- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2010-1821
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1121
IBM WebSphere Application Server 7.0, 8.0, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : websphere_application_server- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1127
IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos... Read more
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1132
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-1122
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.... Read more
Affected Products : security_guardium- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-1088
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, the kernel does not properly clear the memory of the kld_file_stat structure before filling the data. Since the structure filled by the k... Read more
Affected Products : freebsd- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1113
IBM Rational Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
Affected Products : rational_team_concert- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15579
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.... Read more
Affected Products : php_melody- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15537
The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature, does not correctly handle attempts to set reserved bits in the xstate header via the ptrace() or rt_sigr... Read more
Affected Products : linux_kernel- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15539
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.... Read more
Affected Products : zorovavi\/blog- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15583
The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that specifies a file for display or for use as a template. The filename is not validated; an attacker could retrieve any file.... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15573
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15575
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified othe... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15568
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15647
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.... Read more
Affected Products : routerfiberhome_firmware- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15574
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15578
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.... Read more
Affected Products : php_melody- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15702
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port... Read more
Affected Products : qpid_broker-j- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025